5 ms·
This is great news for DDOSers! </end_irony> 80% of threats and DDOS attacks we receive come from Hetzner IPs! We stopped wasting time reporting this to Hetzne
by globile 9y ago
This is great news for DDOSers! </end_irony>
80% of threats and DDOS attacks we receive come from Hetzner IPs! We stopped wasting time reporting this to Hetzner and simply block whole IP ranges in Cloudflare. Sad but true.
- nh2 9y agoIP range blocking is extremely bad practice. You'll lose customers that way. It's like rejecting email addresses that don't end with .com. There are lots of services these days that can "smartly" handle DoS attacks (e.g. only drop traffic from an IP in the range when it starts flooding you).
- Nokinside 9y agoSorry for my ignorance, but how likely it is that customer traffic originates from Hetzner servers? Maybe someone runs VPN's trough them?
- globile 9y agoThis is one possible explanation. For example, You'd be surprised how many people run intrusion attacks from Kaperskys VPN service.... You see Kaperskys IPS on your logs and wonder...
- globile 9y agoRange blocking is the last resort, and we've only done it after alerting Hetzner and getting no response. In any case, we only block for a few hours.... and yes, you definitely risk losing clients. I know Hetzner is not only DE based and many user cases for IPs originating are possible, but luckily DE is not our market.
- malikNF 9y agoWouldn't cloudflare block these attacks automatically for you? I used cloudflare on a server that used to get dossed often and the attacks are now almost non existent when we got cloudflare in-front of us. Range blocking is a really silly thing to do don't you think? Hope you guys find a better way that that. Something tells me your application might be leaking your site's IP?
- globile 9y agoYes, sorry, should be more specific. DDOS are blocked, but intrusion attacks not so much. Although cloudflare has also a Web application firewall, somethings always slip thru. Re: range blocking, only very specifically and when it got out of hand...and just for a few hours. Not a good solution, I agree
- ryanlol 9y ago>80% of threats and DDOS attacks we receive come from Hetzner IPs! Sorry, this doesn't sound believable in the slightest.
- groupthink-- 9y agoyes it does. hetzner easy accounts for half of ours. are you actually involved in mitigating attacks, or do you think it just sounds unbelievable?
- globile 9y agoOk, true. Some clarification is necessary. We get hit everyday by 1-2 intrusion attacks as well as a few DDOS a month...and the intrusion attacks are mostly from anonymised address or singled-out ISP IPs...but of the ones that come from Cloud based organisations, 80% or more is Hetzner. We've never seen attacks from AWS/Google Cloud/Rackspace, etc... but Hetzner shows up in our logs a lot.
- mschuster91 9y ago> but of the ones that come from Cloud based organisations, 80% or more is Hetzner. Probably because people renting servers from Hetzner, OVH and friends run them once and keep them running without upgrading the OS and software which means they will get pwned (and a pwned hexacore server with 1 or 10Gbit gives you pretty good resources compared to an AWS micro instance)... while AWS disincentivizes you from doing so. In addition AWS tries to enforce security with its heavy reliance on security rules, which adds another layer of security - after all no one can hack your mysqld when it's not exposed to the Internet...